Malware Log Analysis

shared / u/worth-dare-5831
content copied

content

Start:: CreateRestorePoint: CloseProcesses: PowerShell: Remove-MpPreference -ExclusionPath "D:\Games" PowerShell: Remove-MpPreference -ExclusionProcess "C:\Users\adith\eclipse\java-2025-06\eclipse\eclipse.exe" PowerShell: Remove-MpPreference -ExclusionProcess "C:\Users\adith\eclipse\dsl-2025-06\eclipse\eclipse.exe" PowerShell: Remove-MpPreference -ExclusionPath "C:\Program Files (x86)\DODI-Repacks" 2026-07-12 20:36 - 2026-07-12 20:36 - 000000000 ____D C:\Users\adith\AppData\Roaming\RenPy CustomCLSID: HKU\S-1-5-21-135322348-1857756456-1324541188-1001_Classes\CLSID\{23B3E3D8-C162-4A8B-AB0C-0905DCB1DF19}\InprocServer32 -> C:\Users\adith\AppData\Local\Packages\Microsoft.PowerAutomateDesktop_8wekyb3d8bbwe\TempState\RDP\DVCPlugin\x64\Microsoft.Flow.RPA.Desktop.UIAutomation.RDP.DVC.Plugin.dll => No File ContextMenuHandlers1: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File ContextMenuHandlers4: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File ContextMenuHandlers5: [DriveFS 28 or later] -> {EE15C2BD-CECB-49F8-A113-CA1BFC528F5B} => -> No File Shortcut: C:\Users\adith\OneDrive\Desktop\games\Play Grand Theft Auto V.lnk -> C:\Program Files (x86)\DODI-Repacks\Grand Theft Auto V\PlayGTAV.bat (No File) AlternateDataStreams: C:\Users\adith\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Asphalt 9: Legends.lnk [1634] FirewallRules: [{ECFE5C2B-E669-4D8D-97F6-D1FEF9867C83}] => (Allow) C:\Users\adith\Downloads\Sekiro - Shadows Die Twice [FitGirl Repack]\setup.exe => No File FirewallRules: [{64A4BCA6-67F0-4BD5-B5D8-339CC9E14075}] => (Allow) C:\Users\adith\Downloads\Sekiro - Shadows Die Twice [FitGirl Repack]\setup.exe => No File FirewallRules: [{E11A6ACC-3E0C-4D0F-9D95-CEF0435FD0AE}] => (Allow) C:\Users\adith\Downloads\Sekiro - Shadows Die Twice [FitGirl Repack]\setup.exe => No File FirewallRules: [{CB53802F-9609-4448-BB4F-C6703C8ABB3C}] => (Allow) C:\Users\adith\Downloads\Sekiro - Shadows Die Twice [FitGirl Repack]\setup.exe => No File FirewallRules: [UDP Query User{82A447D5-CEC8-400A-A232-B9D98C5B733C}C:\users\adith\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\adith\appdata\local\programs\opera gx\opera.exe => No File FirewallRules: [TCP Query User{8E133776-7836-467E-884A-71D8D9930853}C:\users\adith\appdata\local\programs\opera gx\opera.exe] => (Allow) C:\users\adith\appdata\local\programs\opera gx\opera.exe => No File FirewallRules: [{1FC43346-3ABD-4FC4-A397-C877986B707B}] => (Allow) C:\Program Files\Blackmagic Design\DaVinci Resolve\ElementsPanelDaemon.exe => No File FirewallRules: [{8A56FA87-46FC-47B8-8302-3562B75C1B4B}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe => No File FirewallRules: [{24A6F5E1-8FF0-42CC-97B2-5393DF716CE9}] => (Allow) C:\Program Files\4DDiG Partition Manager\4DDiG Partition Manager.exe => No File FirewallRules: [{E8D0D570-3AA4-4C25-99D3-910E498A7FF2}] => (Allow) C:\Program Files\4DDiG Partition Manager\4DDiG Partition Manager.exe => No File FirewallRules: [{948D2351-A4E2-4DE0-9F3E-9076B8DE43BA}] => (Allow) C:\Program Files\4DDiG Partition Manager\NetFrameCheck.exe => No File FirewallRules: [{CDF40143-1647-4DC2-A8FA-1A414F4AD842}] => (Allow) C:\Program Files\4DDiG Partition Manager\NetFrameCheck.exe => No File FirewallRules: [{6A70C8E6-C084-4A9C-A4AA-D02DFB77E559}] => (Allow) C:\Program Files\4DDiG Partition Manager\Monitor\Monitor.exe => No File FirewallRules: [{6CC06557-1849-4A0D-BCAC-EC890AE212D4}] => (Allow) C:\Program Files\4DDiG Partition Manager\Monitor\Monitor.exe => No File FirewallRules: [{FD352AF9-67C2-4FF4-9CC2-89D53EF11B2B}] => (Allow) C:\Program Files (x86)\4DDiG DLL Fixer\4DDiG DLL Fixer.exe => No File FirewallRules: [{76A8ACCF-5871-49FC-A64E-F91659C3543E}] => (Allow) C:\Program Files (x86)\4DDiG DLL Fixer\4DDiG DLL Fixer.exe => No File FirewallRules: [{17761D7B-ABA7-4575-88DF-72D57E334946}] => (Allow) C:\Program Files (x86)\4DDiG DLL Fixer\NetFrameCheck.exe => No File FirewallRules: [{004F917D-CECE-4E1B-86AC-07B55FC9DA7C}] => (Allow) C:\Program Files (x86)\4DDiG DLL Fixer\NetFrameCheck.exe => No File FirewallRules: [{5A5EBE77-F53B-4F71-8409-3DBEBBCF4043}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{96767395-E5F3-4BBC-B453-D86D44A4D551}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{2158939A-03A5-4E95-AFD7-0E62A0E774F8}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{8712A066-4D84-46F9-A0E8-C25D4FE76C64}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{C78B80B3-C5D3-4222-961A-9E0E05F57196}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File FirewallRules: [{E1E72295-D913-4B12-B881-C4E3C7B421F3}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe => No File HKU\S-1-5-19\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-20\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-21-135322348-1857756456-1324541188-1001\...\Run: [Windscribe] => "C:\Program Files\Windscribe\Windscribe.exe" --autostart (No File) HKU\S-1-5-21-135322348-1857756456-1324541188-1001\...\MountPoints2: {b4fab8d0-cd0b-11ef-af1c-2c98113a1736} - "E:\Autorun.exe" HKU\S-1-5-21-135322348-1857756456-1324541188-1007\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-80-1374824361-465945973-1635723809-3190017912-3513974881\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-80-2642945258-3347507153-3616503272-4135775549-3697934295\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-80-266611377-2988282937-918524641-2313297942-2584230755\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-80-3597395555-777427886-1086645810-985234469-869121811\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-80-3850495238-697030721-643989029-4057494824-707097437\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-80-526369210-1730866775-3035121100-1937364911-2593483836\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) HKU\S-1-5-18\...\Run: [GoogleDriveFS] => C:\Program Files\Google\Drive File Stream\111.0.2.0\GoogleDriveFS.exe --startup_mode (No File) Task: {120E45A6-0441-48ED-B727-1BEA18C50A43} - System32\Tasks\McAfee\DAD.WPS.Execute.Updates => "C:\Program Files\McAfee\WPS\1.7.209.1\dad\mc-dad.exe" (No File) Task: {8A6750D7-D937-40C5-BB86-F945BC312C39} - System32\Tasks\Microsoft\Windows\Location\Notifications => %windir%\System32\LocationNotificationWindows.exe (No File) Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File) S4 OracleJobSchedulerFREE; "c:\app\adith\product\23ai\dbhomefree\Bin\extjob.exe" FREE (No File) S4 OracleJobSchedulerXE; "c:\app\adith\product\21c\dbhomexe\Bin\extjob.exe" XE (No File) S2 OracleOraDB21Home1MTSRecoveryService; "C:\app\adith\product\21c\dbhomeXE\bin\omtsreco.exe" OracleOraDB21Home1MTSRecoveryService (No File) S2 OracleOraDB21Home1TNSListener; "C:\app\adith\product\21c\dbhomeXE\BIN\TNSLSNR" (No File) S2 OracleOraDB23Home1TNSListener; "C:\app\adith\product\23ai\dbhomeFree\BIN\TNSLSNR" (No File) S2 OracleServiceFREE; "c:\app\adith\product\23ai\dbhomefree\bin\ORACLE.EXE" FREE (No File) S3 OracleServiceXE; "c:\app\adith\product\21c\dbhomexe\bin\ORACLE.EXE" XE (No File) S2 OracleVssWriterFREE; "C:\app\adith\product\23ai\dbhomeFree\bin\OraVSSW.exe" FREE (No File) S2 OracleVssWriterXE; "C:\app\adith\product\21c\dbhomeXE\bin\OraVSSW.exe" XE (No File) U1 bdvedisk; no ImagePath S3 MpKsl24b20dbb; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AB6379EC-58DD-41D0-9C3B-D8A7433C0E73}\MpKslDrv.sys (No File) HKU\S-1-5-21-135322348-1857756456-1324541188-1001\Software\Classes\regfile: <==== ATTENTION HKU\S-1-5-21-135322348-1857756456-1324541188-1001\Software\Classes\.reg: => <==== ATTENTION HKU\S-1-5-21-135322348-1857756456-1324541188-1001\Software\Classes\.bat: => <==== ATTENTION HKU\S-1-5-21-135322348-1857756456-1324541188-1001\Software\Classes\.cmd: => <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION HKU\S-1-5-21-135322348-1857756456-1324541188-1001\...\Run: [MicrosoftEdgeAutoLaunch_257719E262E8BC315525EC125FE54180] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-09] (Microsoft Corporation -> Microsoft Corporation) HKU\S-1-5-21-135322348-1857756456-1324541188-1007\...\Run: [MicrosoftEdgeAutoLaunch_8D6AADF2653E934432CCA87C0AED8CC3] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start [4970824 2026-07-09] (Microsoft Corporation -> Microsoft Corporation) Task: {A47642E1-CEDE-40B5-AC82-54829974FA04} - System32\Tasks\Activation-Renewal => C:\Program Files\Activation-Renewal\Activation_task.cmd [17463 2025-01-16] () [File not signed] -> Task C:\Program Files\Activation-Renewal CMD: Type "C:\Users\adith\enhancements_final.js" CMD: Type "C:\Users\adith\Untitled-1.js" StartPowershell: # Replace /scanonly with /clean if you also want to delete items -- however, this will activate a trial license on the system, I do not recommend it $hmpExe = "$env:TEMP\HitmanPro_x64.exe" $logFile = "$env:TEMP\HitmanPro_ScanLog.txt" Invoke-WebRequest -Uri "https://dl.surfright.nl/HitmanPro_x64.exe" -OutFile $hmpExe -UseBasicParsing $proc = Start-Process $hmpExe -ArgumentList "/ews","/scanonly","/noinstall","/log=`"$logFile`"","/logtype=txt" -Wait -PassThru if (!(Test-Path $logFile)) { Write-Host "Scan failed (exit $($proc.ExitCode))"; exit 1 } Get-Content $logFile -Encoding Unicode EndPowershell: StartPowerShell: # Downloads newest AdwCleaner version directly from Malwarebytes, performs an update, scans, cleans and writes the log in console # Does not clean preinstalled objects, only PUP/Adware # If you would like to delete preinstalled objects, add an argument /preinstalled to the /clean argument # If you would like to only scan with it, change the argument from /clean to /scan # NOTE: For the sake of users from Asia (primarily China), do not use the clean option. It will very likely remove a lot of their important software. New-Item -ItemType Directory -Force -Path "$env:SystemDrive\AdwCleaner" | Out-Null Invoke-WebRequest -Uri "https://adwcleaner.malwarebytes.com/adwcleaner?channel=release" -OutFile "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/eula" -Wait -WindowStyle Hidden $logFile = "$env:SystemDrive\AdwCleaner\AdwCleanerOutputFRST.txt" Start-Process -FilePath "$env:SystemDrive\AdwCleaner\AdwCleanerFRST.exe" -ArgumentList "/noreboot /clean" -Wait -WindowStyle Hidden -RedirectStandardOutput $logFile Get-Content $logFile -Encoding Unicode Remove-Item -Path $logFile -Force -ErrorAction SilentlyContinue EndPowerShell: Comment: List Windows Defender properties, settings StartPowerShell: function Write-Section { param([string]$Title) Write-Host "" Write-Host "<=== $Title ===>" } Write-Section "Protection Status" Get-MpComputerStatus | Select-Object AMServiceEnabled, AntispywareEnabled, AntivirusEnabled, BehaviorMonitorEnabled, IoavProtectionEnabled, RealTimeProtectionEnabled, IsTamperProtected, NetworkProtectionStatus | Format-List Write-Section "Signature / Engine Versions" Get-MpComputerStatus | Select-Object AMProductVersion, AMEngineVersion, AntivirusSignatureVersion, AntispywareSignatureVersion | Format-List Write-Section "Preferences / Configuration" Get-MpPreference | Select-Object PUAProtection, MAPSReporting, SubmitSamplesConsent, CheckForSignaturesBeforeRunningScan, CloudBlockLevel, EnableNetworkProtection, DisableScriptScanning, DisableArchiveScanning, DisableRemovableDriveScanning, DisableScanningNetworkFiles, DisableScanningMappedNetworkDrivesForFullScan, DisableBlockAtFirstSeen, DisableHeuristics, DisableAutoExclusions | Format-List Write-Section "Threat Detections" $threats = Get-MpThreatDetection if ($threats) { $threats | Format-Table -AutoSize } else { Write-Host " (no threat detections found)" } EndPowerShell: Comment: List drive info, identify possible damaged drives (thanks to AdvancedSetup from Malwarebytes for parts of these) StartPowerShell: param( [int]$MaxEvents = 2000 ) $GPTTypeMap = @{ 'EBD0A0A2-B9E5-4433-87C0-68B6B72699C7' = 'Microsoft Basic Data' 'E3C9E316-0B5C-4DB8-817D-F92DF00215AE' = 'Microsoft Reserved (MSR)' 'DE94BBA4-06D1-4D40-A16A-BFD50179D6AC' = 'Windows Recovery Environment (WinRE)' 'C12A7328-F81F-11D2-BA4B-00A0C93EC93B' = 'EFI System Partition' '21686148-6449-6E6F-744E-656564454649' = 'BIOS Boot Partition' 'A19D880F-05FC-4D3B-A006-743F0F84911E' = 'OEM Partition' '5808C8AA-7E8F-42E0-85D2-E1E90434CFB3' = 'Cluster Metadata Partition' '48465300-0000-11AA-AA11-00306543ECAC' = 'Apple HFS/HFS+' '7C3457EF-0000-11AA-AA11-00306543ECAC' = 'Apple APFS' '0FC63DAF-8483-4772-8E79-3D69D8477DE4' = 'Linux Filesystem' '0657FD6D-A4AB-43C4-84E5-0933C84B4F4F' = 'Linux Swap' 'E6D6D379-F507-44C2-A23C-238F2A3DF928' = 'Linux LVM' } $MBRTypeMap = @{ '01'='FAT12';'04'='FAT16 <32M';'05'='Extended';'06'='FAT16';'07'='IFS/NTFS/exFAT/HPFS';'0B'='FAT32 CHS';'0C'='FAT32 LBA';'0E'='FAT16 LBA' '0F'='Extended LBA';'82'='Linux Swap';'83'='Linux Native';'8E'='Linux LVM';'A5'='FreeBSD';'A6'='OpenBSD';'A8'='Mac OS X';'AB'='Mac OS X Boot' 'AF'='Mac OS X HFS';'EE'='EFI GPT Protective';'EF'='EFI System Partition' } function Get-PartitionTypeInfo { param($Partition) $guid = $null if ($Partition.GptType) { $guid = ($Partition.GptType -replace '[{}]', '').ToUpper() } if ([string]::IsNullOrWhiteSpace($guid) -or $guid -eq '00000000-0000-0000-0000-000000000000') { $guid = switch ($Partition.Type) { "System" { "C12A7328-F81F-11D2-BA4B-00A0C93EC93B" } "Reserved" { "E3C9E316-0B5C-4DB8-817D-F92DF00215AE" } "Basic" { "EBD0A0A2-B9E5-4433-87C0-68B6B72699C7" } "Recovery" { "DE94BBA4-06D1-4D40-A16A-BFD50179D6AC" } default { $null } } } if ($guid) { $name = $GPTTypeMap[$guid] if ($name) { return "$name (GPT GUID: $($guid.ToLower()))" } else { return "Unknown/Custom (GPT GUID: $($guid.ToLower()))" } } if ($Partition.MbrType) { $code = ($Partition.MbrType.ToString() -replace '^0x', '').PadLeft(2, '0').ToUpper() $name = $MBRTypeMap[$code] if ($name) { return "$name (MBR code: 0x$code)" } else { return "Unknown/Custom (MBR code: $($Partition.MbrType))" } } return $Partition.Type } function Get-DrMapping { param([int]$MaxEvents) $map = @{} try { $events = Get-WinEvent -FilterHashtable @{ LogName = 'System'; ProviderName = 'disk' } -MaxEvents $MaxEvents -ErrorAction Stop } catch { return $map } foreach ($e in $events) { if ($e.Message -match 'Harddisk(\d+)\\DR(\d+)') { $n = [int]$Matches[1] $dr = [int]$Matches[2] if (-not $map.ContainsKey($n)) { $map[$n] = $dr } } } return $map } $drMap = Get-DrMapping -MaxEvents $MaxEvents $physicalDisks = Get-PhysicalDisk | Select-Object DeviceId, FriendlyName, SerialNumber, MediaType, @{N='SizeGB';E={[math]::Round($_.Size / 1GB,2)}} foreach ($pd in $physicalDisks) { $devId = [int]$pd.DeviceId $drSuffix = if ($drMap.ContainsKey($devId)) { "\DR$($drMap[$devId])" } else { '\DR? (no event seen yet)' } Write-Host "" Write-Host "<=== \Device\Harddisk$devId$drSuffix ($($pd.FriendlyName)) ===>" Write-Host " DeviceId: $devId | Serial: $($pd.SerialNumber) | Media: $($pd.MediaType) | Size: $($pd.SizeGB) GB" try { $partitions = Get-Partition -DiskNumber $devId -ErrorAction Stop if (-not $partitions) { Write-Host " (no partitions found)" continue } foreach ($part in $partitions) { $driveLetter = if ($part.DriveLetter) { "$($part.DriveLetter):" } else { 'no letter' } $sizeGB = [math]::Round($part.Size / 1GB, 2) $typeInfo = Get-PartitionTypeInfo -Partition $part Write-Host " [PARTITION $($part.PartitionNumber)] Drive: $driveLetter - $sizeGB GB - $typeInfo" } } catch { Write-Host " [ERROR] cannot read partitions for disk $devId" } } if ($drMap.Count -eq 0) { Write-Host "" Write-Host "Note: no \Device\HarddiskN\DRx entries found in the last $MaxEvents System log events. Increase -MaxEvents, or the DR number will only appear once Windows actually logs a disk event for that drive (e.g. a bad block warning)." } EndPowerShell: Comment: Verify that Discord does not have any injected code to intercept personal data. If anything is prompted here, it needs to be checked that it isn't malicious code. Powershell: @("$env:APPDATA","$env:LOCALAPPDATA") | ForEach-Object { Get-ChildItem $_ -Recurse -Filter "index.js" -ErrorAction SilentlyContinue } | Where-Object { $_.FullName -match "discord_desktop_core" } | ForEach-Object { Write-Host "--- $($_.FullName) ---"; (Get-Content $_.FullName -Raw).Substring(0,[Math]::Min(2000,(Get-Content $_.FullName -Raw).Length)) } StartPowerShell: # Basic BSOD listings $ccKey = "HKLM:\SYSTEM\CurrentControlSet\Control\CrashControl" $cfg = Get-ItemProperty $ccKey -ErrorAction SilentlyContinue $dumpTypeMap = @{0='None';1='Complete';2='Kernel';3='Minidump';7='Automatic'} Write-Output "--- Configuration ---" Write-Output ("Dump Type: {0} ({1})" -f $cfg.CrashDumpEnabled, $dumpTypeMap[$cfg.CrashDumpEnabled]) Write-Output ("Full Dump Path: {0}" -f $(if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"})) Write-Output ("Minidump Folder: {0}" -f $(if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"})) Write-Output ("Auto Reboot: {0}" -f $(if($cfg.AutoReboot -eq 0){'Disabled'}else{'Enabled'})) Write-Output "--- Found Dump Files ---" $full = if($cfg.DumpFile){[Environment]::ExpandEnvironmentVariables($cfg.DumpFile)}else{"$env:SystemRoot\MEMORY.DMP"} if (Test-Path $full) { Get-Item $full | Select Name,Length,LastWriteTime | Format-Table -AutoSize } $mini = if($cfg.MinidumpDir){[Environment]::ExpandEnvironmentVariables($cfg.MinidumpDir)}else{"$env:SystemRoot\Minidump"} if (Test-Path $mini) { Get-ChildItem $mini -Filter *.dmp | Select Name,Length,LastWriteTime | Format-Table -AutoSize } Write-Output "--- BugCheck Reasoning (recent events) ---" $map = @{ '0x0000000A'='IRQL_NOT_LESS_OR_EQUAL - faulty/outdated driver accessed memory at high IRQL' '0x0000001E'='KMODE_EXCEPTION_NOT_HANDLED - unhandled kernel exception, often driver/hardware' '0x0000002E'='DATA_BUS_ERROR - typically bad RAM or hardware fault' '0x0000003B'='SYSTEM_SERVICE_EXCEPTION - exception in a system service, often driver-related' '0x00000050'='PAGE_FAULT_IN_NONPAGED_AREA - bad RAM or faulty driver/antivirus' '0x0000007A'='KERNEL_DATA_INPAGE_ERROR - disk-related problem' '0x0000007B'='INACCESSIBLE_BOOT_DEVICE - system could not find/access the boot device' '0x0000007E'='SYSTEM_THREAD_EXCEPTION_NOT_HANDLED - almost always a faulty driver' '0x0000007F'='UNEXPECTED_KERNEL_MODE_TRAP - hardware issue (CPU/RAM/overclocking)' '0x0000009F'='DRIVER_POWER_STATE_FAILURE - driver failed to respond to a power state change' '0x000000C2'='BAD_POOL_CALLER - driver mishandling memory (pool corruption)' '0x000000D1'='DRIVER_IRQL_NOT_LESS_OR_EQUAL - typically a network or GPU driver' '0x000000EF'='CRITICAL_PROCESS_DIED - a critical system process died, often malware/system corruption' '0x00000116'='VIDEO_TDR_FAILURE - GPU driver failed to respond in time (timeout)' '0x00000124'='WHEA_UNCORRECTABLE_ERROR - hardware fault (CPU/RAM/PSU/overclocking)' '0x00000133'='DPC_WATCHDOG_VIOLATION - faulty driver or storage subsystem issue' '0x00000139'='KERNEL_SECURITY_CHECK_FAILURE - corrupted kernel structure, possibly malware' } $events = Get-WinEvent -FilterHashtable @{LogName='System';Id=1001} -MaxEvents 100 -ErrorAction SilentlyContinue | Where-Object { $_.ProviderName -match 'WER-SystemErrorReporting' } | Select-Object -First 5 if (-not $events) { Write-Output "No BugCheck events found in the log." } foreach ($ev in $events) { $code = if ($ev.Message -match 'bugcheck was:\s*(0x[0-9A-Fa-f]+)') { $matches[1] } else { $null } Write-Output ("Time: {0}" -f $ev.TimeCreated) Write-Output ("Code: {0}" -f $(if($code){$code}else{'not recognized'})) if ($code -and $map.ContainsKey($code.ToUpper())) { Write-Output ("Meaning: {0}" -f $map[$code.ToUpper()]) } elseif ($code) { Write-Output "Meaning: unknown code, look up at learn.microsoft.com/windows-hardware/drivers/debugger/bug-check-code-reference2" } Write-Output "" } EndPowerShell: StartPowerShell: # This snippet lists all installed apps and their folder contents along with SHA256 hashes. Useful for troubleshooting malware abusing installed app entry. param( [switch]$Recurse, [int]$MaxFilesPerApp = [int]::MaxValue ) $uninstallPaths = @( 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*', 'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*', 'HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*' ) $script:msiInstaller = $null function Get-MsiInstallLocation { param([string]$ProductCode) if (-not $script:msiInstaller) { try { $script:msiInstaller = New-Object -ComObject WindowsInstaller.Installer } catch { return $null } } try { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallLocation') if ([string]::IsNullOrWhiteSpace($loc)) { $loc = $script:msiInstaller.ProductInfo($ProductCode, 'InstallSource') } if ([string]::IsNullOrWhiteSpace($loc)) { return $null } return $loc } catch { return $null } } function Get-CleanPath { param([string]$RawValue) if ([string]::IsNullOrWhiteSpace($RawValue)) { return $null } $s = $RawValue.Trim() if ($s.StartsWith('"')) { $endQuote = $s.IndexOf('"', 1) if ($endQuote -gt 0) { return $s.Substring(1, $endQuote - 1) } } if ($s -match '^(.*?\.exe)\b') { return $Matches[1] } return $s } function Format-FileSize { param([long]$Bytes) if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) } if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) } if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) } return "$Bytes B" } $script:PeExtensions = @('.exe', '.dll', '.sys', '.ocx', '.cpl', '.scr', '.drv', '.efi', '.msi', '.msp', '.msu') function Test-IsPeFile { param([string]$Extension) return $script:PeExtensions -contains $Extension.ToLower() } function Get-SignatureInfo { param([string]$Path, [string]$Extension) if (-not (Test-IsPeFile -Extension $Extension)) { return [PSCustomObject]@{ Signer = 'N/A (not PE)'; Status = 'NotApplicable'; Valid = $false } } $result = [PSCustomObject]@{ Signer = 'Unsigned'; Status = 'NotSigned'; Valid = $false } try { $sig = Get-AuthenticodeSignature -LiteralPath $Path -ErrorAction Stop $result.Status = $sig.Status.ToString() $result.Valid = ($sig.Status -eq 'Valid') if ($sig.SignerCertificate) { if ($sig.SignerCertificate.Subject -match 'CN=([^,]+)') { $result.Signer = $Matches[1].Trim('"') } else { $result.Signer = $sig.SignerCertificate.Subject } if (-not $result.Valid) { $result.Signer += " [INVALID: $($result.Status)]" } } elseif ($sig.Status -eq 'NotSigned') { $result.Signer = 'Unsigned' } else { $result.Signer = "Unknown [$($result.Status)]" } } catch { $result.Signer = 'Verification error' $result.Status = 'Error' $result.Valid = $false } return $result } $rawApps = Get-ItemProperty -Path $uninstallPaths -ErrorAction SilentlyContinue | Where-Object { $_.DisplayName -and $_.DisplayName.Trim() -ne '' } | Select-Object @{Name = 'Name'; Expression = { $_.DisplayName } }, @{Name = 'Version'; Expression = { $_.DisplayVersion } }, @{Name = 'Publisher'; Expression = { $_.Publisher } }, @{Name = 'InstallFolder'; Expression = { if ($_.InstallLocation -and $_.InstallLocation.Trim() -ne '') { $_.InstallLocation } elseif ($_.UninstallString -match 'MsiExec\.exe.*?(\{[0-9A-Fa-f\-]{36}\})') { $productCode = $Matches[1] $msiLoc = Get-MsiInstallLocation -ProductCode $productCode if ($msiLoc) { $msiLoc } else { "MSI: $productCode (location not found)" } } elseif ($_.UninstallString) { $_.UninstallString } else { 'N/A' } } } | Sort-Object Name -Unique foreach ($app in $rawApps) { $versionText = if ($app.Version) { $app.Version } else { '?' } $publisherText = if ($app.Publisher) { $app.Publisher } else { '?' } Write-Host "" Write-Host "<=== $($app.Name) [$versionText] ($publisherText) ===>" if ($app.InstallFolder -eq 'N/A' -or $app.InstallFolder -match '^MSI: .* \(location not found\)$') { Write-Host " Path: $($app.InstallFolder)" continue } $cleanPath = Get-CleanPath -RawValue $app.InstallFolder $exists = $false try { $exists = Test-Path -LiteralPath $cleanPath -ErrorAction Stop } catch [System.UnauthorizedAccessException] { Write-Host " Path: $cleanPath" Write-Host " [ACCESS DENIED]" continue } catch { Write-Host " Path: $cleanPath" Write-Host " [ERROR] cannot access" continue } if (-not $exists) { Write-Host " Path: $cleanPath" Write-Host " [NOT FOUND]" continue } $rootItem = Get-Item -LiteralPath $cleanPath -Force $created = $rootItem.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $modified = $rootItem.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') if ($rootItem.PSIsContainer) { $subFolders = Get-ChildItem -LiteralPath $cleanPath -Directory -Force -ErrorAction SilentlyContinue $gciParams = @{ LiteralPath = $cleanPath; File = $true; Force = $true; ErrorAction = 'SilentlyContinue' } if ($Recurse) { $gciParams['Recurse'] = $true } $allFiles = Get-ChildItem @gciParams Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: $($allFiles.Count) | Folders: $($subFolders.Count)" foreach ($dir in $subFolders) { $dCreated = $dir.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $dModified = $dir.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') $dFileCount = (Get-ChildItem -LiteralPath $dir.FullName -File -Force -ErrorAction SilentlyContinue).Count Write-Host (" [DIR] {0} - {1} - {2,10} - {3}" -f $dCreated, $dModified, "$dFileCount files", $dir.FullName) } } else { $allFiles = @($rootItem) Write-Host " Path: $cleanPath | Created: $created | Modified: $modified | Files: 1" } if ($allFiles.Count -eq 0) { continue } $shown = $allFiles | Select-Object -First $MaxFilesPerApp foreach ($f in $shown) { $hash = 'N/A' try { $hash = (Get-FileHash -LiteralPath $f.FullName -Algorithm SHA256 -ErrorAction Stop).Hash } catch { $hash = 'HASH-ERROR' } $size = Format-FileSize -Bytes $f.Length $fcreated = $f.CreationTime.ToString('dd/MM/yyyy HH:mm:ss') $fmod = $f.LastWriteTime.ToString('dd/MM/yyyy HH:mm:ss') $sigInfo = Get-SignatureInfo -Path $f.FullName -Extension $f.Extension Write-Host (" [{0}] {1} - {2} - {3,10} - Signer: {4} - {5}" -f $hash, $fcreated, $fmod, $size, $sigInfo.Signer, $f.FullName) } } EndPowerShell: Comment: List 30 recent scheduled tasks (you know, just for the sake of it) Powershell: Get-ScheduledTask | select -first 30 | Get-ScheduledTaskInfo Comment: List recent Run (Windows + R) executed commands, useful for identifying ClickFix attacks Powershell: (Get-ItemProperty "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU" -ErrorAction SilentlyContinue).PSObject.Properties | Where-Object { $_.Name -match "^[a-z]$" } | ForEach-Object { Write-Host "$($_.Name): $($_.Value)" } Comment: Remove browser cache StartPowerShell: $ProfilesDirectory = (Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList').ProfilesDirectory $DisplayNames = @{ "chrome" = "Chrome" "firefox" = "Firefox" "opera" = "Opera" "operagx" = "Opera GX" "brave" = "Brave" "msedge" = "Edge" "vivaldi" = "Vivaldi" "librewolf" = "LibreWolf" "mullvad" = "Mullvad Browser" "zen" = "Zen" } $ProcessNameMap = @{ "operagx" = "opera" "mullvad" = "mullvadbrowser" } $trueCacheNames = @("Cache", "Code Cache", "DawnCache", "GPUCache", "GrShaderCache", "ShaderCache", "Shared Dictionary\cache") function Get-CacheDirs { param([string]$BrowserName, [string]$ProfilesDirectory) switch ($BrowserName) { "chrome" { $dir = "$ProfilesDirectory\*\AppData\Local\Google\Chrome\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "firefox" { $dir = "$ProfilesDirectory\*\AppData\Local\Mozilla\Firefox\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "opera" { $dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software" $r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software" $r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $r1 + $r2 } "operagx" { $dir1 = "$ProfilesDirectory\*\AppData\Local\Opera Software\Opera GX Stable" $r1 = Get-ChildItem $dir1 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $dir2 = "$ProfilesDirectory\*\AppData\Roaming\Opera Software\Opera GX Stable" $r2 = Get-ChildItem $dir2 -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } $r1 + $r2 } "brave" { $dir = "$ProfilesDirectory\*\AppData\Local\BraveSoftware\Brave-Browser\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "msedge" { $dir = "$ProfilesDirectory\*\AppData\Local\Microsoft\Edge\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "vivaldi" { $dir = "$ProfilesDirectory\*\AppData\Local\Vivaldi\User Data" Get-ChildItem $dir -Directory -Recurse -Include $trueCacheNames -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName } } "librewolf" { $dir = "$ProfilesDirectory\*\AppData\Local\LibreWolf\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "mullvad" { $dir = "$ProfilesDirectory\*\AppData\Local\Mullvad\MullvadBrowser\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } "zen" { $dir = "$ProfilesDirectory\*\AppData\Local\zen\Profiles" Get-ChildItem $dir -Directory -Recurse -Include "cache2" -ErrorAction SilentlyContinue | ForEach-Object { $_.FullName + '\entries' } } } } function Format-Size { param([long]$Bytes) if ($Bytes -ge 1GB) { return '{0:N2} GB' -f ($Bytes / 1GB) } if ($Bytes -ge 1MB) { return '{0:N2} MB' -f ($Bytes / 1MB) } if ($Bytes -ge 1KB) { return '{0:N2} KB' -f ($Bytes / 1KB) } return "$Bytes B" } $BrowserKeys = @('chrome', 'firefox', 'opera', 'operagx', 'brave', 'msedge', 'vivaldi', 'librewolf', 'mullvad', 'zen') foreach ($key in $BrowserKeys) { $procName = if ($ProcessNameMap.ContainsKey($key)) { $ProcessNameMap[$key] } else { $key } Get-Process -Name $procName -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue } Start-Sleep -Seconds 5 $grandBytes = 0L $grandFiles = 0 $anyFound = $false foreach ($key in $BrowserKeys) { $cacheDirs = Get-CacheDirs -BrowserName $key -ProfilesDirectory $ProfilesDirectory if (-not $cacheDirs -or $cacheDirs.Count -eq 0) { continue } $anyFound = $true $displayName = $DisplayNames[$key] $browserBytes = 0L $browserFiles = 0 foreach ($cacheDir in $cacheDirs) { if (-not (Test-Path $cacheDir)) { continue } $items = Get-ChildItem -Path $cacheDir -Force -Recurse -ErrorAction SilentlyContinue $files = $items | Where-Object { -not $_.PSIsContainer } $bytes = ($files | Measure-Object -Property Length -Sum).Sum if (-not $bytes) { $bytes = 0 } $browserFiles += $files.Count $browserBytes += $bytes Get-ChildItem -Path "$cacheDir\*" -Force -ErrorAction SilentlyContinue | Remove-Item -Force -Recurse -ErrorAction SilentlyContinue } $grandBytes += $browserBytes $grandFiles += $browserFiles Write-Host ("{0,-16} freed {1,10} ({2} files)" -f $displayName, (Format-Size $browserBytes), $browserFiles) } if (-not $anyFound) { Write-Host "No cache found for any installed browser." } Write-Host "" Write-Host ("Total freed: {0} ({1} files)" -f (Format-Size $grandBytes), $grandFiles) EndPowerShell: Comment: Verify WMI repository, repair & verify again CMD: winmgmt.exe /verifyrepository CMD: winmgmt.exe /salvagerepository CMD: winmgmt.exe /verifyrepository Comment: To rebuild the performance counter library values CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R" CMD: "%WINDIR%\SysWOW64\lodctr.exe /R" CMD: "C:\Windows\SYSTEM32\lodctr.exe /R" CMD: "C:\Windows\SysWOW64\lodctr.exe /R" Comment: Resync performance counter library values to WMI as well CMD: winmgmt.exe /resyncperf Comment: Force policy removal C:\Windows\System32\GroupPolicyUsers C:\Windows\System32\GroupPolicy CMD: gpupdate.exe /force Comment: Reset PowerShell execution policy Powershell: Set-ExecutionPolicy Unrestricted -Scope CurrentUser -Force Comment: BITS reset Startbatch: @echo off net.exe stop BITS ipconfig.exe /flushdns ren "%programdata%\Microsoft\Network\Downloader\qmgr*.*" qmgr*.*.old net.exe start BITS Endbatch: cmd: bitsadmin.exe /reset /allusers Comment: Network reset commands CMD: netsh.exe int ip reset CMD: netsh.exe int ipv6 reset CMD: ipconfig.exe /flushDNS CMD: netsh.exe winsock reset catalog Comment: Additional temp file removal C:\Windows\System32\config\systemprofile\AppData\Local\*.tmp C:\WINDOWS\system32\*.tmp C:\WINDOWS\syswow64\*.tmp C:\Users\CurrentUserName\AppData\Local\Temp\* C:\Windows\Temp\* C:\Windows\SystemTemp\* C:\Windows\Prefetch\* Comment: System repair commands CMD: SFC.exe /scannow CMD: DISM.exe /Online /Cleanup-image /Restorehealth EmptyTemp: End::